-
-
Notifications
You must be signed in to change notification settings - Fork 70
Bump the npm-dependencies group across 1 directory with 15 updates #910
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Bump the npm-dependencies group across 1 directory with 15 updates #910
Conversation
|
Thanks for your first pull request! We appreciate your contribution. |
|
Here's the code health analysis summary for commits Analysis Summary
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Bumps the npm-dependencies group with 13 updates in the / directory: | Package | From | To | | --- | --- | --- | | [@tailwindcss/cli](https://github.com/tailwindlabs/tailwindcss/tree/HEAD/packages/@tailwindcss-cli) | `4.1.17` | `4.1.18` | | [esbuild](https://github.com/evanw/esbuild) | `0.25.12` | `0.27.1` | | [glob](https://github.com/isaacs/node-glob) | `11.0.3` | `13.0.0` | | [rollup](https://github.com/rollup/rollup) | `4.53.2` | `4.53.3` | | [@cloudflare/vitest-pool-workers](https://github.com/cloudflare/workers-sdk/tree/HEAD/packages/vitest-pool-workers) | `0.9.14` | `0.10.15` | | [@eslint/js](https://github.com/eslint/eslint/tree/HEAD/packages/js) | `9.39.1` | `9.39.2` | | [@npmcli/arborist](https://github.com/npm/cli/tree/HEAD/workspaces/arborist) | `9.1.6` | `9.1.9` | | [@vitest/coverage-istanbul](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-istanbul) | `3.2.4` | `4.0.15` | | [@vitest/coverage-v8](https://github.com/vitest-dev/vitest/tree/HEAD/packages/coverage-v8) | `3.2.4` | `4.0.15` | | [eslint](https://github.com/eslint/eslint) | `9.39.1` | `9.39.2` | | [lerna](https://github.com/lerna/lerna/tree/HEAD/packages/lerna) | `9.0.0` | `9.0.3` | | [prettier](https://github.com/prettier/prettier) | `3.6.2` | `3.7.4` | | [vitest](https://github.com/vitest-dev/vitest/tree/HEAD/packages/vitest) | `3.2.4` | `4.0.15` | Updates `@tailwindcss/cli` from 4.1.17 to 4.1.18 - [Release notes](https://github.com/tailwindlabs/tailwindcss/releases) - [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.1.18/packages/@tailwindcss-cli) Updates `esbuild` from 0.25.12 to 0.27.1 - [Release notes](https://github.com/evanw/esbuild/releases) - [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG.md) - [Commits](evanw/esbuild@v0.25.12...v0.27.1) Updates `glob` from 11.0.3 to 13.0.0 - [Changelog](https://github.com/isaacs/node-glob/blob/main/changelog.md) - [Commits](isaacs/node-glob@v11.0.3...v13.0.0) Updates `rollup` from 4.53.2 to 4.53.3 - [Release notes](https://github.com/rollup/rollup/releases) - [Changelog](https://github.com/rollup/rollup/blob/master/CHANGELOG.md) - [Commits](rollup/rollup@v4.53.2...v4.53.3) Updates `tailwindcss` from 4.1.17 to 4.1.18 - [Release notes](https://github.com/tailwindlabs/tailwindcss/releases) - [Changelog](https://github.com/tailwindlabs/tailwindcss/blob/main/CHANGELOG.md) - [Commits](https://github.com/tailwindlabs/tailwindcss/commits/v4.1.18/packages/tailwindcss) Updates `@cloudflare/vitest-pool-workers` from 0.9.14 to 0.10.15 - [Release notes](https://github.com/cloudflare/workers-sdk/releases) - [Changelog](https://github.com/cloudflare/workers-sdk/blob/main/packages/vitest-pool-workers/CHANGELOG.md) - [Commits](https://github.com/cloudflare/workers-sdk/commits/@cloudflare/[email protected]/packages/vitest-pool-workers) Updates `@eslint/js` from 9.39.1 to 9.39.2 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](https://github.com/eslint/eslint/commits/v9.39.2/packages/js) Updates `@npmcli/arborist` from 9.1.6 to 9.1.9 - [Release notes](https://github.com/npm/cli/releases) - [Changelog](https://github.com/npm/cli/blob/latest/workspaces/arborist/CHANGELOG.md) - [Commits](https://github.com/npm/cli/commits/arborist-v9.1.9/workspaces/arborist) Updates `@vitest/coverage-istanbul` from 3.2.4 to 4.0.15 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.15/packages/coverage-istanbul) Updates `@vitest/coverage-v8` from 3.2.4 to 4.0.15 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.15/packages/coverage-v8) Updates `eslint` from 9.39.1 to 9.39.2 - [Release notes](https://github.com/eslint/eslint/releases) - [Commits](eslint/eslint@v9.39.1...v9.39.2) Updates `lerna` from 9.0.0 to 9.0.3 - [Release notes](https://github.com/lerna/lerna/releases) - [Changelog](https://github.com/lerna/lerna/blob/main/packages/lerna/CHANGELOG.md) - [Commits](https://github.com/lerna/lerna/commits/v9.0.3/packages/lerna) Updates `prettier` from 3.6.2 to 3.7.4 - [Release notes](https://github.com/prettier/prettier/releases) - [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md) - [Commits](prettier/prettier@3.6.2...3.7.4) Updates `vitest` from 3.2.4 to 4.0.15 - [Release notes](https://github.com/vitest-dev/vitest/releases) - [Commits](https://github.com/vitest-dev/vitest/commits/v4.0.15/packages/vitest) Updates `wrangler` from 4.44.0 to 4.54.0 - [Release notes](https://github.com/cloudflare/workers-sdk/releases) - [Commits](https://github.com/cloudflare/workers-sdk/commits/[email protected]/packages/wrangler) --- updated-dependencies: - dependency-name: "@tailwindcss/cli" dependency-version: 4.1.18 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: esbuild dependency-version: 0.27.1 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: glob dependency-version: 13.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: rollup dependency-version: 4.53.3 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: tailwindcss dependency-version: 4.1.18 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: "@cloudflare/vitest-pool-workers" dependency-version: 0.10.15 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: "@eslint/js" dependency-version: 9.39.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: "@npmcli/arborist" dependency-version: 9.1.9 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: "@vitest/coverage-istanbul" dependency-version: 4.0.15 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: "@vitest/coverage-v8" dependency-version: 4.0.15 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: eslint dependency-version: 9.39.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: lerna dependency-version: 9.0.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: npm-dependencies - dependency-name: prettier dependency-version: 3.7.4 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies - dependency-name: vitest dependency-version: 4.0.15 dependency-type: direct:development update-type: version-update:semver-major dependency-group: npm-dependencies - dependency-name: wrangler dependency-version: 4.54.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: npm-dependencies ... Signed-off-by: dependabot[bot] <[email protected]>
eba6174 to
214897b
Compare
| "devDependencies": { | ||
| "@11ty/eleventy": "^3.1.2", | ||
| "@cloudflare/vitest-pool-workers": "^0.9.1", | ||
| "@cloudflare/vitest-pool-workers": "^0.11.0", |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Bug: The updated vitest version ^4.0.16 is incompatible with the peer dependency range (2.0.x - 3.2.x) of @cloudflare/vitest-pool-workers@^0.11.0, which will break the test suite.
Severity: CRITICAL | Confidence: High
🔍 Detailed Analysis
The pull request updates vitest to version ^4.0.16 while also using @cloudflare/vitest-pool-workers@^0.11.0. The @cloudflare/vitest-pool-workers package has a peer dependency requirement for vitest in the range of 2.0.x - 3.2.x. Since version 4.0.16 is outside this compatible range, package managers will report unmet peer dependency errors. This mismatch will cause the test suite to fail at runtime, specifically breaking tests in the packages/cfsite/ package which relies on vitest-pool-workers for Cloudflare Workers testing, thus blocking the CI pipeline.
💡 Suggested Fix
Update @cloudflare/vitest-pool-workers to a version that is compatible with vitest v4.x. If no such version is available, revert the vitest upgrade to a version within the 2.0.x - 3.2.x range to resolve the peer dependency conflict.
🤖 Prompt for AI Agent
Review the code at the location below. A potential bug has been identified by an AI
agent.
Verify if this is a real issue. If it is, propose a fix; if not, explain why it's not
valid.
Location: package.json#L49
Potential issue: The pull request updates `vitest` to version `^4.0.16` while also using
`@cloudflare/vitest-pool-workers@^0.11.0`. The `@cloudflare/vitest-pool-workers` package
has a peer dependency requirement for `vitest` in the range of `2.0.x - 3.2.x`. Since
version `4.0.16` is outside this compatible range, package managers will report unmet
peer dependency errors. This mismatch will cause the test suite to fail at runtime,
specifically breaking tests in the `packages/cfsite/` package which relies on
`vitest-pool-workers` for Cloudflare Workers testing, thus blocking the CI pipeline.
Did we get this right? 👍 / 👎 to inform future reviews.
Reference ID: 7625010
Bumps the npm-dependencies group with 13 updates in the / directory:
4.1.174.1.180.25.120.27.111.0.313.0.04.53.24.53.30.9.140.10.159.39.19.39.29.1.69.1.93.2.44.0.153.2.44.0.159.39.19.39.29.0.09.0.33.6.23.7.43.2.44.0.15Updates
@tailwindcss/clifrom 4.1.17 to 4.1.18Release notes
Sourced from
@tailwindcss/cli's releases.Changelog
Sourced from
@tailwindcss/cli's changelog.Commits
9b32f7cRelease v4.1.18 (#19431)164194dDon’t try reading from pipes or special file descriptors (#19421)563a016Only use the last value when parsing duplicate cli arguments (#19416)0e8f075Fix source map generation during when watching files on the CLI (#19373)Maintainer changes
This version was pushed to npm by malfaitrobin, a new releaser for
@tailwindcss/clisince your current version.Updates
esbuildfrom 0.25.12 to 0.27.1Release notes
Sourced from esbuild's releases.
... (truncated)
Changelog
Sourced from esbuild's changelog.
... (truncated)
Commits
5e0e56dpublish 0.27.1 to npm5a89732fix #4354: improve IIFE inlining for expressionsb940218minify: move unused expr simplification laterc46d498fix #4353: remove emptytry/finallyclauses7a72735fix #4348: bundler bug withvarinsideif4e4e177fix #4351: label +try+forminifier bugd6427c9fix: deno release url wrong comment (#4326)48e3e19callingSymbol.forwith a primitive never throws4ff88d0updatedecorator-tests.jssnapshot1877e60callingSymbolwith a primitive will never throwMaintainer changes
This version was pushed to npm by [GitHub Actions](https://www.npmjs.com/~GitHub Actions), a new releaser for esbuild since your current version.
Updates
globfrom 11.0.3 to 13.0.0Changelog
Sourced from glob's changelog.
... (truncated)
Commits
3bfb96013.0.0db31a63Split the CLI out from the main project5493458ci: remove node 203f7526ctest: fix bin tests on windows (slashes)2b03cca12.0.0d56203dprettier configbb521e5Remove --shell option where unsafe to use2551fb511.1.047473c0bin: Do not expose filenames to shell expansionbc33fe1skip tilde test on systems that lack tilde expansionUpdates
rollupfrom 4.53.2 to 4.53.3Release notes
Sourced from rollup's releases.
Changelog
Sourced from rollup's changelog.
Commits
998b5954.53.3ef834c2Tracing the importers chain for exported variables in external module (#6182)fb21d56Check if left side is included when checking if assigning to an assignment ha...4b4581dAdd test-install CI job to test packaging, installation and importing of roll...18ee41bfix(deps): lock file maintenance minor/patch updates (#6180)f0a80d1Re-enable TypeScript test (#6174)Updates
tailwindcssfrom 4.1.17 to 4.1.18Release notes
Sourced from tailwindcss's releases.
Changelog
Sourced from tailwindcss's changelog.
Commits
9b32f7cRelease v4.1.18 (#19431)820d907ExposecandidatesToAstto the language server (#19405)478e959Don’t emit color-mix fallback rules inside@keyframes(#19419)a5f4644Validate named values in candidate parser (#19397)229121dCanonicalization: combinetext-*andleading-*classes (#19396)243615eHandle backwards compatibility forcontenttheme from JS configs (#19381)7642751Improve compatibility with special default values in JS configs (#19348)af48117remove unnecessary intermediate check9e436f7Try to canonicalize any arbitrary utility to a bare value (#19379)479b725Bump Vitest to v4 (#19216)Updates
@cloudflare/vitest-pool-workersfrom 0.9.14 to 0.10.15Release notes
Sourced from
@cloudflare/vitest-pool-workers's releases.... (truncated)
Changelog
Sourced from
@cloudflare/vitest-pool-workers's changelog.... (truncated)
Commits
d9eae49Version Packages (#11538)8672321Version Packages (#11511)0c71b87Version Packages (#11503)1b3e10dVersion Packages (#11427)ed5186eadd tests for vitest-pool-workers context exports (#11441)f87b057Version Packages (#11374)86eab8eVersion Packages (#11356)9cd9b96Debugging vitest-pool-workers flakes (#11358)9f3cfc2Version Packages (#11334)e5ec8cfBump the workerd-and-workers-types group with 2 updates (#11318)Updates
@eslint/jsfrom 9.39.1 to 9.39.2Release notes
Sourced from
@eslint/js's releases.Commits
c43ce24chore: package.json update for@eslint/jsreleaseUpdates
@npmcli/arboristfrom 9.1.6 to 9.1.9Release notes
Sourced from
@npmcli/arborist's releases.